Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 23 Jun 1999 02:00:59 -0500 (EST)
From:      Alfred Perlstein <bright@rush.net>
To:        Jerry Raynor <jerryr@ComCAT.COM>
Cc:        questions@FreeBSD.ORG
Subject:   Re: HELP HACKER!!!
Message-ID:  <Pine.BSF.3.96.990623015757.14320w-100000@cygnus.rush.net>
In-Reply-To: <Pine.GSO.4.02A.9906222003440.7244-100000@uw>

next in thread | previous in thread | raw e-mail | index | archive | help
On Tue, 22 Jun 1999, Jerry Raynor wrote:

> I caught someone who had just got in and setup a user account!!  hwo di I
> find out how they got it????  This is my first encounter with this, what
> steps should I take??  Thanks!!  I'm useing FreeBSD-2.2.5-R  I've changed
> my password and root's password already

most likely you've been hit with the BSD procfs hole, my suggestion?
upgrade to 2.2.8 and in the future try to keep ahead of such holes,
by staying somewhat current and keeping in touch with the freebsd
mailing lists and CERT advisories.

http://www.freebsd.org/handbook/stable.html
http://www.freebsd.org/security/security.html

-Alfred



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.96.990623015757.14320w-100000>